Computer is running better already i really appreciate the help...
HIJACK THIS LOG
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:14, on 3/19/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\taskswitch.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\devldr32.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Administrator\Desktop\HiJackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R3 - URLSearchHook: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2FFB00B3-AC14-4769-9E72-DA94E4E3824B} - C:\WINDOWS\System32\gebyx.dll (file missing)
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: {506b188a-a119-10c9-6ca4-cd71397a55dc} - {cd55a793-17dc-4ac6-9c01-911aa881b605} - C:\WINDOWS\System32\caaobijq.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\System32\taskswitch.exe
O4 - HKLM\..\Run: [5011ee3b] rundll32.exe "C:\WINDOWS\System32\rigwejfu.dll",b
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/windowsupd...b?1203883812328O20 - Winlogon Notify: ddcccbx - ddcccbx.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
--
End of file - 4670 bytes
COMBOFIX LOG
ComboFix 08-03-18.1 - Administrator 2008-03-19 14:57:26.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.1.1252.1.1033.18.178 [GMT -5:00]
Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
* Created a new restore point
[color=\"red\"]
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/color]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\curity~1
C:\WINDOWS\BM5322dda7.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\iwxiwwvh.dll
C:\WINDOWS\system32\urqqrsq.dll
C:\WINDOWS\system32\vpcaaewo.dll
C:\WINDOWS\system32\xgbksxob.dll
C:\WINDOWS\system32\xybeg.ini
C:\WINDOWS\system32\xybeg.ini2
.
((((((((((((((((((((((((( Files Created from 2008-02-19 to 2008-03-19 )))))))))))))))))))))))))))))))
.
2008-03-18 22:16 . 2008-03-18 22:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-03-18 22:16 . 2008-03-18 22:16 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Yahoo!
2008-03-18 22:13 . 2008-03-19 14:07 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-03-18 22:09 . 2008-03-18 22:12 <DIR> d-------- C:\Program Files\Yahoo!
2008-03-17 14:54 . 2008-03-17 22:47 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AVG7
2008-03-17 14:53 . 2008-03-17 14:53 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-03-17 14:53 . 2008-03-17 14:53 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-17 14:53 . 2008-03-17 23:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-03-17 14:42 . 2008-03-17 14:42 <DIR> d-------- C:\Program Files\Alwil Software
2008-03-17 14:42 . 2003-03-18 15:20 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll
2008-03-17 14:22 . 2008-03-17 14:22 <DIR> d-------- C:\WINDOWS\Sun
2008-03-17 12:23 . 2008-03-17 12:23 294 --ahs---- C:\WINDOWS\system32\ufjewgir.ini
2008-03-16 12:22 . 2008-03-16 12:27 414 --ahs---- C:\WINDOWS\system32\lhtrywxh.ini
2008-03-16 12:21 . 2008-03-16 12:21 63 --a------ C:\WINDOWS\system32\5011fcb5
2008-03-16 12:13 . 2008-03-16 12:13 37,376 --a------ C:\WINDOWS\mrofinu572.exe
2008-03-13 13:26 . 2008-03-13 13:26 <DIR> d-------- C:\Program Files\Hasbro Interactive
2008-03-13 13:26 . 1999-12-09 13:17 755,200 --a------ C:\WINDOWS\system32\Ir50_32.dll
2008-03-13 13:26 . 1999-12-09 13:18 239,616 --a------ C:\WINDOWS\system32\Hdk3ctnt.dll
2008-03-13 13:26 . 1999-12-09 13:17 199,680 --a------ C:\WINDOWS\system32\iac25_32.ax
2008-03-13 13:26 . 2008-03-13 13:27 405 --a------ C:\WINDOWS\PowerReg.dat
2008-03-05 18:49 . 2008-03-05 18:49 <DIR> d-------- C:\Program Files\Lavasoft
2008-03-05 18:48 . 2008-03-05 18:48 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-04 22:50 . 2008-03-04 22:53 <DIR> d-------- C:\Program Files\Google
2008-03-04 22:50 . 2008-03-19 03:57 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Google Updater
2008-02-28 22:28 . 2008-02-28 22:28 <DIR> d-------- C:\Program Files\Mplayer
2008-02-28 22:26 . 2008-02-28 22:26 <DIR> d-------- C:\Program Files\Quake III Arena
2008-02-28 14:15 . 2008-02-28 22:28 871 --a------ C:\WINDOWS\QIII.INI
2008-02-28 05:38 . 2008-02-28 05:38 0 --a------ C:\WINDOWS\nsreg.dat
2008-02-27 19:36 . 2008-02-27 19:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\MSN6
2008-02-27 19:36 . 2008-02-27 19:36 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\MSN6
2008-02-27 19:33 . 2008-02-27 19:33 <DIR> d-------- C:\WINDOWS\LogFiles
2008-02-27 19:03 . 2008-02-27 19:03 <DIR> d-------- C:\Program Files\Common Files\INCA Shared
2008-02-27 19:03 . 2003-07-20 22:17 5,174 --a------ C:\WINDOWS\system32\nppt9x.vxd
2008-02-27 19:03 . 2005-01-04 13:43 4,682 --a------ C:\WINDOWS\system32\npptNT2.sys
2008-02-26 16:41 . 2008-03-05 18:49 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-26 02:10 . 2008-02-26 02:10 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2008-02-26 02:10 . 1998-10-29 16:45 306,688 --a------ C:\WINDOWS\IsUninst.exe
2008-02-26 01:47 . 2008-02-27 20:41 <DIR> d-------- C:\Program Files\Diablo II backup
2008-02-25 19:07 . 2008-02-25 19:07 94,208 --a------ C:\WINDOWS\DIIUnin.exe
2008-02-25 19:07 . 2008-02-26 02:01 35,535 --a------ C:\WINDOWS\DIIUnin.dat
2008-02-25 19:07 . 2008-02-25 19:07 2,829 --a------ C:\WINDOWS\DIIUnin.pif
2008-02-25 18:57 . 2008-03-18 18:19 <DIR> d-------- C:\Program Files\Diablo II
2008-02-25 17:35 . 2008-02-25 17:35 <DIR> d-------- C:\Program Files\D-Tools
2008-02-25 17:35 . 2004-08-22 16:31 155,136 --a------ C:\WINDOWS\system32\drivers\d347bus.sys
2008-02-25 17:35 . 2004-08-22 16:31 5,248 --a------ C:\WINDOWS\system32\drivers\d347prt.sys
2008-02-25 16:19 . 2008-02-26 01:50 21,840 --a----t- C:\WINDOWS\system32\SIntfNT.dll
2008-02-25 16:19 . 2008-02-26 01:50 17,212 --a----t- C:\WINDOWS\system32\SIntf32.dll
2008-02-25 16:19 . 2008-02-26 01:50 12,067 --a----t- C:\WINDOWS\system32\SIntf16.dll
2008-02-25 03:50 . 2005-04-15 19:58 1,071,088 --a------ C:\WINDOWS\system32\MSCOMCTL.OCX
2008-02-25 03:50 . 2004-03-09 16:45 662,288 --a------ C:\WINDOWS\system32\MSCOMCT2.OCX
2008-02-25 03:50 . 2004-06-14 14:56 427,864 --a------ C:\WINDOWS\system32\XceedZip.dll
2008-02-25 03:33 . 2008-02-25 03:33 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\CyberLink
2008-02-25 03:31 . 2008-03-16 15:04 <DIR> d--h----- C:\Program Files\InstallShield Installation Information
2008-02-25 03:31 . 2008-02-25 03:34 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\CyberLink
2008-02-25 03:29 . 2008-02-25 03:28 505,392 --a------ C:\WINDOWS\system32\msvcp71.dll
2008-02-25 03:28 . 2008-02-25 03:31 <DIR> d-------- C:\Program Files\CyberLink
2008-02-24 23:37 . 2008-02-24 23:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
2008-02-24 23:36 . 2008-02-24 23:37 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\DAEMON Tools Pro
2008-02-24 23:29 . 2008-02-24 23:29 685,816 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2008-02-24 23:23 . 2008-02-24 23:23 <DIR> d-------- C:\Program Files\DNA
2008-02-24 23:23 . 2008-02-24 23:23 <DIR> d-------- C:\Program Files\BitTorrent
2008-02-24 23:23 . 2008-03-16 12:33 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\DNA
2008-02-24 23:23 . 2008-03-18 21:30 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\BitTorrent
2008-02-24 21:22 . 2008-02-24 21:35 <DIR> d-------- C:\Program Files\Videos
2008-02-24 21:20 . 2008-02-24 21:20 <DIR> d-------- C:\Program Files\TweakNow RegCleaner Std
2008-02-24 21:18 . 2008-03-10 17:58 <DIR> d-------- C:\Program Files\Downloaded Programs
2008-02-24 21:00 . 2008-02-24 21:00 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Ahead
2008-02-24 19:22 . 2008-02-24 19:22 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AdobeUM
2008-02-24 19:21 . 2008-02-24 19:21 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-02-24 17:54 . 2008-02-24 17:57 <DIR> d-------- C:\Program Files\Winamp
2008-02-24 17:54 . 2008-02-24 17:57 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Winamp
2008-02-24 17:39 . 2008-02-25 19:18 <DIR> d-------- C:\Program Files\torrents
2008-02-24 16:40 . 2008-03-10 21:46 <DIR> d-------- C:\Program Files\Incomplete
2008-02-24 16:39 . 2008-03-17 14:50 <DIR> d-------- C:\Program Files\Media
2008-02-24 16:37 . 2008-03-10 21:47 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\LimeWire
2008-02-24 16:31 . 2007-12-14 01:59 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-02-24 16:30 . 2008-02-24 16:31 <DIR> d-------- C:\Program Files\Java
2008-02-24 16:28 . 2008-02-24 16:28 <DIR> d-------- C:\Program Files\Common Files\Java
2008-02-24 16:27 . 2008-02-24 18:16 <DIR> d-------- C:\Program Files\LimeWire
2008-02-24 15:27 . 2008-02-24 15:27 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Aim
2008-02-24 15:25 . 2008-03-19 14:45 <DIR> d-------- C:\Program Files\Viewpoint
2008-02-24 15:25 . 2008-02-24 15:25 <DIR> d-------- C:\Program Files\AOD
2008-02-24 15:25 . 2008-02-26 02:27 <DIR> d-------- C:\Program Files\AIM
2008-02-24 15:25 . 2004-02-25 13:05 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2008-02-24 15:11 . 2007-07-30 19:19 549,720 --a------ C:\WINDOWS\system32\wuapi.dll
2008-02-24 15:11 . 2007-07-30 19:19 325,976 --a------ C:\WINDOWS\system32\wucltui.dll
2008-02-24 15:11 . 2007-07-30 19:19 216,408 --a------ C:\WINDOWS\system32\wuaucpl.cpl
2008-02-24 15:11 . 2007-07-30 19:19 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2008-02-24 15:11 . 2007-07-30 19:18 34,136 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-02-24 15:11 . 2007-07-30 19:18 33,624 --a------ C:\WINDOWS\system32\wups.dll
2008-02-24 15:11 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-02-24 15:11 . 2007-07-30 19:19 25,944 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-02-24 15:11 . 2007-07-30 19:18 20,312 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2008-02-24 09:39 . 2001-08-17 12:20 96,256 --a------ C:\WINDOWS\system32\drivers\ac97intc.sys
2008-02-24 09:39 . 2001-08-17 12:20 96,256 --a--c--- C:\WINDOWS\system32\dllcache\ac97intc.sys
2008-02-23 10:19 . 2008-02-23 10:19 <DIR> d---s---- C:\Documents and Settings\Administrator\UserData
2008-02-22 17:09 . 2008-02-22 17:09 <DIR> d---s---- C:\WINDOWS\system32\Microsoft
2008-02-22 17:02 . 2008-03-19 14:45 <DIR> d-------- C:\Program Files\Symantec
2008-02-22 17:02 . 2008-03-19 14:41 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
2008-02-22 17:02 . 2008-02-22 17:02 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Symantec
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-16 16:52 12,464 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2008-02-22 16:53 --------- d-----w C:\Program Files\microsoft frontpage
2008-02-22 16:52 558,142 ----a-w C:\WINDOWS\java\Packages\JBP37BB7.ZIP
2008-02-22 16:52 155,995 ----a-w C:\WINDOWS\java\Packages\MSA8BHJD.ZIP
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2FFB00B3-AC14-4769-9E72-DA94E4E3824B}]
C:\WINDOWS\System32\gebyx.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{cd55a793-17dc-4ac6-9c01-911aa881b605}]
C:\WINDOWS\System32\caaobijq.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 17:43 4670704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CoolSwitch"="C:\WINDOWS\System32\taskswitch.exe" [2002-03-19 12:30 45632]
"5011ee3b"="C:\WINDOWS\System32\rigwejfu.dll" [ ]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-03-17 15:27 579072]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-03-17 14:53 219136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddcccbx]
ddcccbx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=C:\WINDOWS\pss\Google Updater.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\5011ee3b]
C:\WINDOWS\System32\hxwyrthl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BDRegion]
--a------ 2007-11-16 19:20 91432 C:\Program Files\Cyberlink\Shared Files\brs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
--a------ 2008-03-12 20:13 287040 C:\Program Files\DNA\btdna.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM5322dda7]
C:\WINDOWS\System32\vpcaaewo.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Pro Agent]
C:\Program Files\DAEMON Tools Pro\DTProAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeadAIM]
--a------ 2004-02-28 12:12 144896 C:\Program Files\AIM\\DeadAIM.ocm
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
--------- 2007-10-11 12:06 62760 C:\Program Files\CyberLink\PowerDVD\Language\Language.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
--a------ 2001-07-09 06:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--------- 2007-10-28 09:35 72736 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-12-14 03:42 144784 C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\winampa.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\BitTorrent\\bittorrent.exe"=
R2 {95808DC4-FA4A-4C74-92FE-5B863F82066B};{95808DC4-FA4A-4C74-92FE-5B863F82066B};C:\Program Files\CyberLink\PowerDVD\
000.fcl [2007-11-03 00:12]
*Newly Created Service* - ALG
*Newly Created Service* - IPNAT
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-03-19 15:00:56
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{95808DC4-FA4A-4C74-92FE-5B863F82066B}]
"ImagePath"="\??\C:\Program Files\CyberLink\PowerDVD\
000.fcl"
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\System32\devldr32.exe
.
**************************************************************************
.
Completion time: 2008-03-19 15:03:12 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-19 20:03:09